kyverno / kyverno

Cloud Native Policy Management
https://kyverno.io
Apache License 2.0
5.71k stars 873 forks source link

Vulnerabilities detected in kyverno 1.11.3 #9387

Closed mcolmant closed 9 months ago

mcolmant commented 10 months ago

Kyverno Version

1.11.1

Description

Hello,

We are using kyverno version 1.11.3 and several vulnerabilities have been reported.

Screenshot 2024-01-12 at 14 32 10

Thanks for your help and your hard work on kyverno.

Slack discussion

No response

Troubleshooting

welcome[bot] commented 10 months ago

Thanks for opening your first issue here! Be sure to follow the issue template!

LMantovan commented 9 months ago

Hello, in addiction many vulnerabilities are detected in kubectl images used by webhooks. image

Is it possible to update kubectl images since there are new versions?

realshuting commented 9 months ago

Hi @mcolmant - opened https://github.com/kyverno/kyverno/pull/9411 go bump the mentioned three libs.

@LMantovan - what version are you using? We bumped the kubectl image via https://github.com/kyverno/kyverno/pull/9408 in 1.12.0.

LMantovan commented 9 months ago

@realshuting I'm using helm chart 3.1.3 which has 1.11.3 version.

mcolmant commented 9 months ago

@realshuting thanks for your help. When do you plan to release the v1.11.4? Thank you,

realshuting commented 9 months ago

@realshuting thanks for your help. When do you plan to release the v1.11.4? Thank you,

As discussed in the community meeting, we will cut 1.11.4 with these vulnerability fixes. It should be out today.